CVE-2026-103010
Received Received - Intake

Heap-based Buffer Overflow in hMailServer

Vulnerability report for CVE-2026-103010, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in hMailServer's legacy Blowfish decryption routine. A local user without credentials can exploit it by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt. The routine writes past a 255-byte heap buffer, causing a denial of service or potential code execution with LocalSystem privileges.

Detection Guidance

To detect this vulnerability, check the installed version of hMailServer. If it is 6.3.5 or earlier, the system is vulnerable. Use commands like 'hMailServer.exe -v' or check the version in the Windows Control Panel's Programs and Features.

Impact Analysis

An attacker could crash the hMailServer service, leading to downtime. In some cases, they might execute arbitrary code with the highest privileges on the system, potentially taking full control of the affected machine.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially allowing unauthorized code execution or data access. As a local or remote attacker could exploit the heap overflow to crash the service or run arbitrary code with LocalSystem privileges, it may lead to unauthorized data disclosure, modification, or deletion. This violates principles of confidentiality, integrity, and availability required by GDPR and HIPAA.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later to fix the issue. As temporary mitigations, disable the REST API, enable DPAPI protection, restrict DCOM access, and prevent untrusted interactive logons.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103010. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart